CVE-2026-23902
Java vulnerability analysis and mitigation

Overview

CVE-2026-23902 is an Incorrect Authorization vulnerability in Apache DolphinScheduler that allows authenticated users with system login permissions to use tenants not defined on the platform during workflow execution. It affects all versions of Apache DolphinScheduler prior to 3.4.1 (Maven package org.apache.dolphinscheduler:dolphinscheduler-api). The vulnerability was disclosed on April 24, 2026, with the fix available in version 3.4.1. It carries a CVSS v3.1 base score of 8.1 (High) (GitHub Advisory, OSS-Security).

Technical details

The vulnerability is classified as CWE-863 (Incorrect Authorization), meaning the platform fails to correctly validate whether a tenant specified during workflow execution is actually defined and permitted within the system. An authenticated attacker with standard system login credentials can craft workflow execution requests referencing arbitrary or undefined tenant identifiers, bypassing the intended authorization boundary. No user interaction is required, and the attack is conducted over the network with low complexity. The vulnerability was reported by researcher Jihang Yu (OSS-Security, GitHub Advisory).

Impact

Successful exploitation allows authenticated attackers to execute workflows under tenant contexts that are not sanctioned by the platform, potentially gaining unauthorized access to tenant-specific resources, data, and configurations. This can result in high confidentiality and integrity impacts — including unauthorized data access and manipulation across multiple tenant environments — though availability is not directly affected. In multi-tenant deployments, this could enable cross-tenant data exposure and privilege escalation within the workflow execution context (GitHub Advisory, OSS-Security).

Exploitability

There is no public proof-of-concept exploit code available, and no evidence of in-the-wild exploitation has been reported as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.023% (7th percentile), indicating a low near-term probability of exploitation (GitHub Advisory).

Exploitation steps

  1. Authentication: Obtain valid credentials for an Apache DolphinScheduler instance running a version prior to 3.4.1 — any account with system login permissions is sufficient.
  2. Identify workflow execution endpoint: Locate the workflow execution API endpoint (e.g., within the dolphinscheduler-api module) that accepts a tenant parameter as part of the workflow run configuration.
  3. Craft malicious request: Submit a workflow execution request specifying a tenant name or identifier that is not defined or registered within the DolphinScheduler platform, bypassing the expected tenant validation check.
  4. Execute workflow under unauthorized tenant: The platform incorrectly authorizes the request, executing the workflow under the specified undefined tenant context, potentially granting access to resources, file paths, or data associated with that tenant scope.
  5. Access restricted resources: Leverage the unauthorized tenant context to read, modify, or exfiltrate tenant-specific data or configurations that would otherwise be inaccessible (OSS-Security, GitHub Advisory).

Indicators of compromise

  • Logs: DolphinScheduler API logs showing workflow execution requests referencing tenant names not present in the platform's tenant registry; repeated authorization-related log entries from a single authenticated user account.
  • Application Behavior: Workflow executions associated with tenant identifiers that do not appear in the platform's configured tenant list; unexpected access to resources or file paths associated with non-existent tenants.
  • Network: Unusual or high-frequency POST requests to DolphinScheduler workflow execution API endpoints from authenticated sessions, particularly with non-standard tenant parameter values.

Mitigation and workarounds

Users should upgrade Apache DolphinScheduler to version 3.4.1 or later, which contains the fix for this vulnerability (GitHub Advisory, OSS-Security). For organizations unable to patch immediately, implementing network-level access controls to restrict who can reach the DolphinScheduler API and monitoring for workflow execution attempts involving undefined tenants are recommended interim measures. Limiting system login permissions to only trusted users can also reduce the attack surface.

Community reactions

The vulnerability was announced via the Apache OSS-Security mailing list and the Apache announcement list on April 24, 2026, by DolphinScheduler maintainer Wenjun Ruan (OSS-Security, Apache Announce). Social media activity was limited, with brief mentions on Bluesky and Mastodon from security-focused accounts. No significant researcher commentary or major media coverage has been identified beyond standard vulnerability aggregator listings.

Additional resources


SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76904CRITICAL9.8
  • Java logoJava
  • org.geotools.jdbc:gt-jdbc-postgis
NoYesAug 21, 2026
GHSA-mqjf-5f49-2fjhCRITICAL9.8
  • Java logoJava
  • org.geotools:gt-jdbc-postgis
NoYesAug 21, 2026
CVE-2026-61827HIGH8.7
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026
CVE-2026-63202HIGH7.5
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026
CVE-2026-63124HIGH7.5
  • Java logoJava
  • io.netty.incubator:netty-incubator-codec-bhttp
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management